This topic describes the basic operations that you can perform on CloudSSO users. The basic operations include creating a user, viewing user information, modifying basic information about a user, deleting a user, enabling or disabling the logon of a user, and resetting the password of a user.
Create a user
-
Log on to the CloudSSO console.
-
In the left-side navigation pane, choose .
-
On the User page, click Create User.
-
In the Create User panel, enter the user's basic information, and then click OK.
-
Username: Required. The username must be unique within the directory. It can be up to 64 characters long and can contain digits, letters, and the following special characters:
@_-.. -
Name, Display Name, Email Address, and Description: Optional.
-
Status: The user is enabled by default. You can also click the switch to set the status to Disabled. A disabled user cannot log on.
-
-
Click Set Password to set a password for the user.
-
Set a password manually: Click Manual Input, and then enter a custom password.
The password must comply with the configured password policy. For more information, see Configure a password policy.
-
Auto-generate a password: Click System Generate. The system generates a password that you must save immediately.
-
Specify whether to require the user to reset the password upon their next logon: Select The user must reset the password upon the next logon.. This forces the user to set a new password upon their next logon.
-
-
Click OK.
View user information
On the User page, click a username to view the user's information on the following tabs:
-
Click the Details tab to view the user's basic information and associated multi-factor authentication (MFA) devices.
-
Click the Joined Groups tab to view the user's group memberships.
-
Click the Access Assignments tab to view the associated RD accounts and access configuration information.
-
Click the RAM User Provisioning tab to view RAM user provisioning details. For more information about RAM user provisioning, see RAM user provisioning overview.
Modify basic information about a user
-
If System for Cross-domain Identity Management (SCIM) synchronization is enabled, you cannot modify the basic information about the users that are synchronized by using SCIM.
-
Usernames cannot be modified.
-
On the User page, click the username you want to edit.
-
On the Details tab, in the Basic Information section, click Edit User.
-
In the Edit User panel, change the Name, Display Name, Email Address, or Description.
-
Click OK.
Delete a user
Before you delete a user, make sure that the user is not associated with the following resources. Otherwise, the deletion fails.
-
Multi-factor authentication (MFA) devices: You must unbind the MFA devices from the user. For more information, see Unbind an MFA device.
-
Access permissions: You must remove the access permissions on the accounts in your resource directory from the user. For more information, see Remove the existing access permissions on an account in a resource directory.
-
Groups: You must remove the user from groups. For more information, see Remove a user from a group.
If SCIM synchronization is enabled, you cannot delete the users that are synchronized by using SCIM.
-
On the User page, find the user that you want to delete and click Delete in the Actions column.
-
In the Delete User dialog box, click OK.
Enable or disable the logon of a user
-
On the User page, click the name of the user.
-
On the Details tab, in the Basic Information section, enable or disable the user.
-
Enable the logon of the user
-
In the Status field, turn on the switch.
-
In the Enabled? dialog box, click OK.
-
-
Disable the logon of the user
-
In the Status field, turn off the switch.
-
In the Disabled? dialog box, click OK.
WarningUsers in the Disabled state cannot log on to the CloudSSO user portal.
-
-
Reset the password of a user
If a user forgets the password, the password expires, or the password poses security risks, a CloudSSO administrator can reset the password of the user. After you enable SSO logon, the password of a user cannot be reset.
After the password is reset, the CloudSSO administrator must notify the user of the new password. If the CloudSSO administrator does not notify the user of the new password, the user cannot log on to the Alibaba Cloud Management Console.
-
On the User page, click the user's name.
-
On the Details tab, click Reset Password.
-
In the Reset Password panel, set a new password.
-
Set a password manually: Click Manual Input, and then enter a custom password.
The password must comply with the configured password policy. For more information, see Configure a password policy.
-
Auto-generate a password: Click System Generate. The system generates a password that you must save immediately.
-
Specify whether to require the user to reset the password upon their next logon: Select The user must reset the password upon the next logon.. This forces the user to set a new password upon their next logon.
-
-
Click OK.
-
If you auto-generated the password, copy it from the Password Reset dialog box, and then click OK.